Skip to main content

Illinois DoT and Cybrbase collaborate on lower-cost cybersecurity

Six of the state's smaller, rural transit agencies will take part in pilot project
By Adam Hill June 2, 2025 Read time: 2 mins
Smaller transit agencies are "routinely left out of the cybersecurity conversation" (© Phuttaphat Tipsana | Dreamstime.com)

Illinois Department of Transportation (IDoT) is to pilot a group-based cybersecurity vulnerability assessment across six small, and mid-size, rural Illinois transit agencies.

IDoT will work with transportation infrastructure cybersecurity firm Cybrbase with these local agencies, which often have relatively few staff and limited budgets, and are "routinely left out of the cybersecurity conversation".

The pilot will examine where security risks might be and help to mitigate them before they compromise public safety, transportation systems and municipal operations.

The idea is to do this at a "significantly lower" cost than traditional cybersecurity audits, using Cybrbase’s proprietary NIST-CRR-based platform, which is powered by AI.

Cybrbase says it "aims not only to bolster local defences but also to serve as a model, showcasing how state-level transportation agencies, insurance risk pools, and transit agencies can work collaboratively with their local transit agencies to create a more resilient transportation ecosystem".

A recent Mineta Transportation Institute (MTI) study - Does the Transit Industry Understand the Risks of Cybersecurity and are the Risks Being Appropriately Prioritised? - revealed persistent cybersecurity gaps in transit agencies in general, but particularly in small and rural transit agencies across the US.

It noted that "many of these agencies are challenged by outdated technology, and limited resources—making them particularly susceptible to cyberattacks". 

Scott Belcher, senior advisor at Cybrbase, MTI research associate, and former CEO of ITS America, says: “As a transportation leader, IDoT is closely watched by other agencies around the nation who may not be aware that cybersecurity vulnerabilities exist among their transit agencies. This initiative is intended to close that gap.”

The local agencies in the pilot include Decatur Public Transit System, Piatt County Public Transportation, QC Metrolink, Reagan Mass Transit and Warren County Public Transportation.

Each of them will complete its assessment independently and confidentially, but is expected to share best practices across the cohort.

For more information on companies in this article

Related Content

  • Covid turns tolls cashless
    December 23, 2021
    When coronavirus hit, Pennsylvania Turnpike Commission made its long-planned e-tolling system permanent; this made sense, but it was still a difficult decision, explains the organisation’s Carl DeFebo
  • Cities get road priorities right
    March 22, 2022
    Cities including Paris, Milan and London have all announced serious expansions to their bicycling infrastructure over the last few years. The era of active travel is here, finds Alan Dron
  • US eyes European model for Illinois toll road upgrade
    May 30, 2014
    David Crawford welcomes the adoption of European-style ITS technology by the US. The Jane Addams Memorial Tollway in Illinois, US is well on the way towards becoming a ‘smart traffic corridor’, taking full advantage of active traffic management (ATM or ‘managed lanes’) technology that originated in Europe. It is one of the first American toll roads to do so; preliminary work began in 2014 and will continue through to 2016. Jane Addams is one of four toll roads operated by the publicly-owned Illinois State T
  • Monitoring and transparency preserve enforcement's reputation
    July 30, 2012
    What can be done to preserve automated enforcement's reputation in the face of media and public criticism? Here, system manufacturers and suppliers talk about what they think are the most appropriate business models. Recent events in Italy only served to once again to push automated enforcement into the media spotlight. At the heart of the matter were the numerous alleged instances of local authorities and their contract suppliers of enforcement services colluding to illegally shorten amber signal phase tim